CVE-2026-35225: Codesys Ethernetip
High severity, CVSS 8.7. EPSS: 0.6% chance of exploitation in the next 30 days.
An unauthenticated remote attacker is able to exhaust all available TCP connections in the CODESYS EtherNet/IP adapter stack, preventing legitimate clients from establishing new connections.
Affected products
- Codesys Codesys Ethernetip: from 1.0.0.0, before 4.9.0.0 (fixed in 4.9.0.0)
Published 2026-04-23. Last modified 2026-06-17.